RE: [PHP] Security alert and question: semicolon taint

From: Date: Mon, 04 Sep 2000 05:05:09 +0000
Subject: RE: [PHP] Security alert and question: semicolon taint
Groups: php.general 
Request: Send a blank email to php-general+get-15052@lists.php.net to get a copy of this message
Yes, but that's not that big of a worry. Since it would only affect users with malicious intent. At 21:54 9/3/2000 -0700, you wrote:
Do you see a problem with just wrapping all the values in the query with quotes? That would seem like the simple way to do it. But I'll probably go back and error check the tainted values anyway. Speaking of which, does PHP have some sort of taint checking like Perl? Yes, you will get SQL errors if you feed the DB a quoted string when it is expecting a number. -Rasmus


« previous php.general (#15052) next »